Lutril vs C1 (formerly ConductorOne)
C1, the identity platform formerly known as ConductorOne, governs human, non-human and AI identities for Fortune 500 and hypergrowth enterprises, with an MCP Gateway. Lutril delivers access governance for employees and AI agents to mid-market teams, in the EU and in French. Where each fits.
Short answer
C1 and Lutril are the two products on this site that govern AI agents at the tool-call level: both register agents as identities and both enforce policy in front of MCP tool calls. C1 is built for Fortune 500 and hypergrowth enterprises, with 400+ connectors, an open-source connector SDK, Slack and Teams requests and a consumption-billed AI access module; its sub-processors are in the United States and prompt DLP is described as in progress. Lutril is built for mid-market teams: the same request, review and lifecycle outcomes in Slack, Teams and the app UI, prompt DLP shipped in the MCP proxy, a browser extension for shadow SaaS and AI, EU hosting and a French-language product.
Where each one starts
C1 (formerly ConductorOne)
An AI-native identity platform governing access for human, non-human and AI identities, and the control plane for the agentic enterprise: Lifecycle, Access, Comply, LLM Gateway, MCP Gateway, Vault, Worker and Bridge. Rebranded from ConductorOne to C1 in April 2026. San Francisco and Portland, founded late 2020, $79M Series B led by Greycroft in October 2025, more than $100M raised.
Lutril
Access governance for employees and AI agents in one product: discovery from Google Workspace and Microsoft 365, a Chrome extension and code scanning; requests in Slack, Teams and the app UI with automatic expiry; reviews that revoke; HRIS-driven lifecycle; and an MCP proxy with policy on every call, prompt DLP and a global kill switch. Hosted in France, in French and English.
Capability by capability
| Capability | C1 (formerly ConductorOne) | Lutril |
|---|---|---|
| SaaS discovery from IdP sign-in and OAuth grants (Google Workspace, Microsoft 365) | YesShadow apps detected from Okta, Google Workspace and Entra ID logins; OAuth scopes monitoredSource 3 | YesGoogle Workspace and Microsoft 365 sign-in signals and OAuth grants, from the day you connect |
| Browser extension for shadow IT and shadow AI discovery | Not documented | YesChrome extension for the SaaS and AI tools that skip SSO |
| Access reviews whose keep-or-remove decisions execute the revocation | YesPolicy auto-creates a revoke task on denial; connector deprovisions, manual task otherwiseSource 4 | YesDecisions execute in the connected tool; proof in the campaign export |
| Access requests and approvals in Slack | Yes/c1 request in Slack; approve or deny without leaving SlackSource 5 | YesRequests, approvals and expiry warnings in Slack |
| Access requests and approvals in Microsoft Teams | YesApprove and deny in Teams since November 2025; create requests in Teams since early 2026Source 6 | YesSame flow in Microsoft Teams, and in the app UI |
| Just-in-time, time-boxed access that expires on its own | YesTime-limited grants expire automatically with remindersSource 7 | YesOne hour to seven days; an approver can shorten, never extend; auto-revoked |
| Onboarding triggered by the HRIS | YesInbound webhooks for Workday and BambooHR; SAP SuccessFactors connectorSource 8 | YesLucca, PayFit and Eurécia native; other HRIS through the MCP endpoint |
| Offboarding that deprovisions across SaaS, including apps outside SSO | YesDeprovision via connector, IdP, ticket, webhook or manual task; not all connectors support itSource 9 | YesNative connectors plus a universal MCP endpoint for any tool with an API |
| Shadow AI discovery: AI tools and agents in use | YesFinds agents and service accounts across Agentforce, Bedrock, Entra, Okta, GCP, GitHub; scans for MCP configsSource 10 | YesSign-in logs, mailbox scanning, Chrome extension and code scanning |
| AI agent registry with an accountable owner | YesIdentities and NHI dashboard with ownership status; standalone agents get their own identitySource 11 | YesOwner, model and scopes on every agent; offboarded like an employee |
| MCP proxy or gateway enforcing policy on agent tool calls | YesMCP Gateway: identity-aware policy in front of every MCP tool call; approval for high-risk callsSource 11 | YesLutril MCP proxy: policy on every call, WORM log, global kill switch |
| Prompt-level DLP and redaction for LLM traffic | Not offeredLLM Gateway does routing and cost; DLP hooks described as being builtSource 12 | YesDetect and redact PII and secrets in prompts, per-model policy |
| EU hosting and a French-language product | Not offeredSub-processors in the United States; DPA authorises EEA-to-US transfer; no French UI documentedSource 13 | YesOVHcloud, France; product and documentation in French |
| Compliance evidence exports for SOC 2 and ISO 27001 | YesAudit-ready reports on demand; evidence timestamped, attributed and exportableSource 14 | YesCampaign export with decisions and revocation proof, one link |
| Native integrations | Yes400+ prebuilt connectors, plus an open-source connector SDKSource 15 | YesMore than 55 native connectors plus the universal MCP endpoint |
| Published pricing | Not offeredPricing page without figures; platform tiers by managed identities, or usage-based tokensSource 2 | Not offeredOn request |
Choose C1 (formerly ConductorOne) if
- You are a large or hypergrowth enterprise with hybrid infrastructure: Active Directory, LDAP, databases, cloud, and a team to run a platform.
- You need an open-source connector SDK to build integrations for in-house systems.
- US hosting is acceptable and AI agent access can be billed on consumption.
Choose Lutril if
- You are a mid-market company and want agent governance, prompt DLP and a kill switch shipped in one product, priced on the people and agents governed.
- Your data has to stay in the EU, or your team works in French.
- You want a browser extension and mailbox scanning to catch the SaaS and AI tools that never touch the identity provider.
- Reviews and approvals should happen in Slack, Teams or the app UI, not in a web console only.
Questions buyers ask
What is C1, and what happened to ConductorOne?
ConductorOne rebranded to C1 on April 6, 2026; conductorone.com now redirects to c1.ai. The product is the same identity platform, positioned as AI-native and as a control plane for the agentic enterprise, with an MCP Gateway and an LLM Gateway alongside lifecycle, access and compliance modules.
Both have an MCP gateway. What is the difference?
Both put identity-aware policy in front of MCP tool calls and register agents as identities. C1 documents auto-approval for low-risk calls and human approval for high-risk ones, with a consumption-billed AI access module. Lutril's MCP proxy adds prompt-level DLP that redacts PII and secrets before the model sees them, a WORM audit log, a global kill switch, and one MCP endpoint that exposes any connected SaaS tool, all in the base product.
Which one fits a company of 150 to 1,500 people?
C1 targets Fortune 500 and hypergrowth enterprises and also publishes an SMB solution page. Lutril is designed for mid-market teams without an IAM function, with discovery starting the day you connect Google Workspace or Microsoft 365 and requests running where people already work.
Where is each product hosted?
C1's sub-processor list is US-based and its data processing agreement authorises transfers from the EEA to the United States. Lutril is hosted at OVHcloud in France, with Cloudflare at the edge.
Sources
- 1C1 homepageread on September 2, 2026
- 2C1 pricingread on September 2, 2026
- 3C1 docs, shadow appsread on September 2, 2026
- 4C1 docs, policiesread on September 2, 2026
- 5C1 docs, Slack applicationread on September 2, 2026
- 6C1 blog, advanced Microsoft Teams integrationread on September 2, 2026
- 7C1 docs, create requestsread on September 2, 2026
- 8C1 docs, inbound webhooksread on September 2, 2026
- 9C1 docs, provisioningread on September 2, 2026
- 10C1, shadow AI discoveryread on September 2, 2026
- 11C1, MCP Gatewayread on September 2, 2026
- 12C1 blog, AI access management, your questions answeredread on September 2, 2026
- 13C1 legal, sub-processorsread on September 2, 2026
- 14C1, Complyread on September 2, 2026
- 15C1 integrationsread on September 2, 2026
- 16C1 blog, we are C1read on September 2, 2026
- 17C1 press, $79M Series Bread on September 2, 2026
- 18C1 docs, review tasksread on September 2, 2026
Lutril wrote this page. Facts about C1 (formerly ConductorOne) come from their public documentation as of September 2, 2026; states marked "Not documented" mean we found nothing public that confirms or denies the capability. Spotted an error? Write to hello@lutril.com and we will correct it.